Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
2019-10-09T13:15:20.193
2024-11-21T04:32:12.537
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | mbr1515_firmware | - | Yes |
Hardware | netgear | mbr1515 | - | No |
Operating System | netgear | mbr1516_firmware | - | Yes |
Hardware | netgear | mbr1516 | - | No |
Operating System | netgear | dgn2200_firmware | - | Yes |
Hardware | netgear | dgn2200 | - | No |
Operating System | netgear | dgn2200m_firmware | - | Yes |
Hardware | netgear | dgn2200m | - | No |
Operating System | netgear | dgnd3700_firmware | - | Yes |
Hardware | netgear | dgnd3700 | - | No |
Operating System | netgear | wnr2000v2_firmware | - | Yes |
Hardware | netgear | wnr2000v2 | - | No |
Operating System | netgear | wndr3300_firmware | - | Yes |
Hardware | netgear | wndr3300 | - | No |
Operating System | netgear | wndr3400_firmware | - | Yes |
Hardware | netgear | wndr3400 | - | No |
Operating System | netgear | wnr3500_firmware | - | Yes |
Hardware | netgear | wnr3500 | - | No |
Operating System | netgear | wnr834bv2_firmware | - | Yes |
Hardware | netgear | wnr834bv2 | - | No |